SAP Security Note
Medium priority
SAP security note 2842034, "[CVE-2019-0390] Information Disclosure in SAP Data Hub", is a program error note released on November 12, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, SAP Data Hub allows an attacker to access information that would otherwise be restricted. Specifically, connections and their details maintained in Connection Manager are visible to users.
Solution
The policies “sap.dh.developer” and “sap.dh.metadata” should only be assigned in development systems. For productive usage, it is not recommended to assign these policies to users. Instead, connection access should be whitelisted by:
- Creating a policy that provides access to a particular connection.
- Assigning that policy to users who are allowed to access it.
To apply the workaround, update the installation of SAP Data Hub to version 2.7 or above.
Reason and prerequisites
Every user with the policy “sap.dh.connectionsAllRead” has access to all connections within the tenant. By default, these are users with the assigned policies “sap.dh.developer”, “sap.dh.metadata”, and “sap.dh.admin”.
CVSS
Score 5.0 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected components
- DH_FOUNDATION: Version 2
Full note on SAP: SAP Support Launchpad note 2842034
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
